← Back

CVE-2012-2562

nvd nist
Published: May 22, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) TERM, or (7) WIPE command via an SMS message.

Affected (1)

Products: Xelex: Mobiletrack
1 product
Mobiletrack
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.3.7
Running on/withPlatform Versions
Google
Android
All versions

References (10)

Timeline

No history available yet.